This policy explains what personal data botgap.dev (the "Service") handles, why, and your rights. The Service is operated by Apps Vietutd, an independent developer based in Vietnam ("we", "us"). Contact: [email protected].
1. Two kinds of people, two roles
- Account holders (businesses that create bots): we decide how this data is used, so we are the controller.
- Visitors who chat with a bot: the business that runs the bot decides why the chat exists and what happens to it, so that business is the controller and we process the chat on its behalf as a processor. If you chatted with a bot and have a privacy question, contact that business first; you can also contact us.
2. Data we handle
Account holders
- Email address, password (stored hashed) or Google sign-in details (name and profile picture).
- Account settings such as time zone, and plan and subscription status from PayPal (subscription ID, status, renewal dates). We never receive your full card or bank details.
- Your Content: bots, knowledge base entries, settings, and the Discord webhook or Telegram bot token you connect (stored on our server, never shown back in the browser).
- Web pages, PDFs or text you submit to generate FAQ drafts. These are processed once and not stored; only the entries you choose to save are kept.
Visitors chatting with a bot
- Messages you send and the bot's replies.
- A random chat session ID stored in your browser (local storage), so the conversation continues if you reload. On Telegram, your Telegram chat ID is used instead.
- Your IP address, used for abuse and rate limiting, and recorded in short-lived server logs.
- Your browser's time and time zone, so the bot can answer date and time questions correctly.
We do not use advertising or tracking cookies, and we do not sell personal data.
3. Why we use it
- To provide the Service: answer chat messages, run your bots, manage your account and subscription. (Legal basis: contract.)
- To keep the Service secure and fair: rate limits, usage limits, preventing abuse. (Legitimate interests.)
- To show bot owners questions their bot could not answer ("Gap Mining") so they can improve answers. (On behalf of the bot owner.)
- To send important service emails, such as password resets or changes to these policies. (Contract / legitimate interests.)
4. Who processes data for us
| Provider | Purpose | Data |
|---|---|---|
| Google (Gemini API) | Generating answers, embeddings and FAQ drafts | Chat messages, recent conversation context, matching knowledge base entries, submitted sources |
| Google (Sign-In) | Login, if you choose it | Name, email, profile picture |
| PayPal | Payments and subscriptions | Billing details you give PayPal, subscription status |
| Cloudflare | Network security, hosting of chat pages, encrypted backups | Traffic data, backup files |
| Hetzner | Server hosting | All Service data |
| Telegram | Only if the bot owner connects Telegram | Telegram messages with that bot |
| Discord | Only if the bot owner adds a Discord webhook | Copies of chat messages and replies, sent to the owner's channel |
If a bot owner forwards chats to Discord, those copies are kept under the owner's control and Discord's policies, not ours. These providers may process data in countries outside your own, including outside the EU; they use their own safeguards for international transfers (such as Standard Contractual Clauses).
5. How long we keep data
- Chat history for a session: up to 7 days after the last message.
- Unanswered questions (Gap Mining): up to 30 days, or until the bot owner clears them.
- Cached answers to general questions: up to 7 days.
- Server request logs (including IP addresses): 5 days.
- Account data and Your Content: while your account exists. After deletion, it is removed from backups within about 7 days.
6. Your rights
Depending on where you live (for example under the GDPR or UK GDPR), you can ask to access, correct, delete or export your personal data, or object to or restrict how we use it. Email [email protected] and we will reply within 30 days. Bot owners can also export or delete their knowledge base from the console at any time. You may also complain to your local data protection authority.
7. Security
Data is sent over HTTPS. Access to our servers is restricted, secrets such as Telegram tokens are never exposed to browsers, and backups are taken daily. No system is perfectly secure, but we work to protect your data and will notify affected users of a breach as required by law.
8. Children
The console is not intended for people under 16. If you believe a child has given us personal data, contact us and we will delete it.
9. Changes
We may update this policy. We will post the new version here and update the date above, and notify account holders of significant changes by email.